StackRadar

CVE-2019-16777

High

Advisory

Published 13 Dec 2019In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.7
base score, highest
EPSS
0.020
80th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
59
of 17,781 indexed, latest versions
Container images
56
deployed by those charts
Fix available
1 of 2
affected packages

npm Vulnerable to Global node_modules Binary Overwrite

Carried by container images the latest versions of 59 of 17,781 indexed charts deploy, on 56 images.

Affected packageAffected versionsFixed inImages
npmnpm1.0.1, 1.39.1-prel, 3.5.2, 3.10.3+13 more6.13.453
npmdeb3.5.2-0ubuntu4, 6.14.4+ds-1ubuntu2, 9.2.0~ds1-2no fix listed6
OSV records
GHSA-4328-8hgf-7wjrUBUNTU-CVE-2019-16777

Charts affected

59 by stars
ChartLatestAffected imagesRadar Score
openwhiskopenwhisk1.0.01 of 10See more

openwhisk openwhisk 1.0.0

1 of the 10 container images this version deploys carry CVE-2019-16777.

Container imageDigestPackageFixed in
openwhisk/ow-utils:1.0.0c80dba0de3aa
npm@3.5.2-0ubuntu4
npm@3.5.2
no fix listed
6.13.4

Open the chart page →

36,215
hive-selfservice-ui-nodeory0.1.01 of 1See more

hive-selfservice-ui-node ory 0.1.0

1 of the 1 container images this version deploys carry CVE-2019-16777.

Container imageDigestPackageFixed in
oryd/hive-selfservice-ui-node:v0.0.426347ef0a2de
npm@6.12.0
6.13.4

Open the chart page →

1,986
bookinforgnu1.0.01 of 7See more

bookinfo rgnu 1.0.0

1 of the 7 container images this version deploys carry CVE-2019-16777.

Container imageDigestPackageFixed in
istio/examples-bookinfo-ratings-v1:1.14.0eb0f1a725ca8
npm@6.9.0
6.13.4

Open the chart page →

20,462
istio-bookinforgnu1.0.21 of 7See more

istio-bookinfo rgnu 1.0.2

1 of the 7 container images this version deploys carry CVE-2019-16777.

Container imageDigestPackageFixed in
istio/examples-bookinfo-ratings-v1:1.14.0eb0f1a725ca8
npm@6.9.0
6.13.4

Open the chart page →

20,462
logsmo-helm-chart6.0.01 of 6See more

log smo-helm-chart 6.0.0

1 of the 6 container images this version deploys carry CVE-2019-16777.

Container imageDigestPackageFixed in
taskrabbit/elasticsearch-dump:latestc967fe68b9c7
npm@6.12.0
6.13.4

Open the chart page →

29,220
pombasmo-helm-chart6.0.01 of 17See more

pomba smo-helm-chart 6.0.0

1 of the 17 container images this version deploys carry CVE-2019-16777.

Container imageDigestPackageFixed in
taskrabbit/elasticsearch-dump:latestc967fe68b9c7
npm@6.12.0
6.13.4

Open the chart page →

29,220
pachydermstatcan0.5.11 of 4See more

pachyderm statcan 0.5.1

1 of the 4 container images this version deploys carry CVE-2019-16777.

Container imageDigestPackageFixed in
pachyderm/grpc-proxy:0.4.92b27f41d4d02
npm@6.4.1
6.13.4

Open the chart page →

4,967
grafanasvtech-public-helm-charts1.0.01 of 2See more

grafana svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2019-16777.

Container imageDigestPackageFixed in
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
npm@6.14.4+ds-1ubuntu2
no fix listed

Open the chart page →

10,902
helloworldyotron-helm-charts0.1.01 of 1See more

helloworld yotron-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2019-16777.

Container imageDigestPackageFixed in
a5hut0sh/helloworld:1.02ae77620e616
npm@6.5.0-next.0
6.13.4

Open the chart page →

1,309

Container images carrying it

56 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
pachyderm/grpc-proxy:0.4.92b27f41d4d02
npm@6.4.1
6.13.4
1
socialmediamacroscope/smile_graphql:0.3.1c5095e94bc65
npm@5.10.0
6.13.4
1
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
npm@6.14.4+ds-1ubuntu2
no fix listed
1
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
npm@4.2.0
6.13.4
1
willwill/kube-slack:v4.1.1d443017aae98
npm@6.4.1
6.13.4
1
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
npm@1.0.1
6.13.4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.